OpenCms 22

OpenCms 22 is now available as a free download.
OpenCms is one of the most popular Open Source Content Management solutions. This new version has been developed by Alkacon Software GmbH with the support of the international OpenCms developer community.
We have also updated the OpenCms Docker image as well as the OpenCms documentation, the Mercury Template documentation and the OpenCms demo site for this release.
The team at Alkacon Software would like to thank everyone who contributed to this release.
Have fun using OpenCms :-)
- Workplace: Date fields accept 24:00 as midnight of the following day
- Workplace: The link gallery widget no longer uses an iframe
- Workplace: Optional client label in the request context and the session table
- Workplace: Cache app supports time-based cleanup of the image cache with progress reporting
- Workplace: The "About" dialog shows the Java EE version and a shortened Git message
- Workplace: More robust CSV user import with better error handling
- Core API: Detail page resolution without a servlet request
- Core API: Methods to find out where an ADE configuration value is defined
- Core API: Configurable element marker handler for container pages
- Core API: The publish history uses the online path for files moved out of deleted folders
- Core API: Fewer permission cache flushes and cached OU lookups for role checks
- Core API: Custom EL resolver for better JSP performance on Jetty
- Core API: Content extraction policy API for formatters
- Solr: Basic auth credentials for external Solr servers
- Solr: Exclude containers from indexing by name or type via sitemap attributes
- Solr: Option to skip metadata extraction for PDF, RTF and MS Office documents
- Solr: Content fields keep the order of the XML content
- Solr: More reliable clients with fixed timeouts, HTTP/1.1 and proper shutdown
- Solr: Improved normalization of folder values in search queries
- Solr: Search results of an unknown resource type are now permission checked
- WebDAV: All init parameters of the Jackrabbit WebDAV servlet can be configured
- Shell: New commands to add a bookmark with a title and to remove a user from a role
- Gradle build: Updated to Gradle 9.4 with Java 25 support
- Gradle build: Tests migrated to JUnit 6
- Gradle build: Source formatting enforced with Spotless
- Gradle build: New opencms_variant property to add a suffix to generated Maven artifacts
- Libraries: Migrated to commons-fileupload2, commons-email2 and Jakarta Mail
- Libraries: Updated GWT
- Pull request #849 fixes the CSV user import with UTF-8 BOM and improves its error handling, provided by rgaviras (github pull #849)
- Pull request #848 fixes silently swallowed Solr core initialization failures, provided by gallardo (github pull #848)
- Pull request #846 reports a NullPointerException in CmsADEConfigData.hasFormatters() for resource types without a schema, provided by gallardo, not merged but fixed independently (github pull #846)
- Pull request #845 adds the missing HttpOnly flag in CmsFlexResponse#addCookie, provided by Thyodas (github pull #845)
- Pull request #844 fixes typos in the German localization, provided by Rainer559 (github pull #844)
Issues fixed in OpenCms 22
- Security: Fixed remote code execution through static export of .jspx files
- Security: Fixed deserialization vulnerability in the database import
- Security: Fixed XXE vulnerability in OpenOffice document indexing
- Security: Fixed unauthenticated Solr aggregation leak by removing the OpenCmsSolrHandler
- Security: Fixed path traversal through the "exportname" property, reported by pig-tail (https://github.com/pig-tail)
- Security: Fixed issue with login bean accepting protocol-relative redirect URIs, reported by Fushuling (github issue #843)
- Security: Fixed missing HttpOnly flag in CmsFlexResponse#addCookie (github pull #845)
- Fixed category selection when overlapping categories are displayed by repository
- Fixed removing a category from a folder also removing it from all resources in that folder
- Fixed accidental relation removal caused by missing escaping of underscores
- Fixed nested setting includes not being resolved from the ADE configuration
- Fixed content folder type index for types configured in a master configuration
- Fixed inconsistent handling of formatters for types with a missing content definition, also reported in pull request #846
- Fixed default path prefixes in OpenCmsUrlServletFilter also matching longer names, for example "/services" blocking "/services_page"
- Fixed GWT RPC exception messages not reaching the client
- Fixed CmsSolrQuery#createTextQuery for multiple text search fields
- Fixed CmsContainerBean#getSimpleName()
- Fixed MIME types for .ott, .tcl and .tk in opencms-vfs.xml
- Fixed Jetty components pulled in by Solr conflicting with container libraries
OpenCms 22 is available in two variants built from the same code base: a Jakarta variant for Tomcat 10, and a legacy Java EE 8 variant for existing Tomcat 9 installations.
The Jakarta variant (Tomcat 10+ / EE 9+) is not compatible with older OpenCms versions. Templates and other OpenCms developed code needs at least an import change from javax.servlet to jakarta.servlet to be compatible.
The legacy OpenCms 22 variant (Tomcat 9 / EE 8) is backwards compatible with all OpenCms versions from 10 to 21. Templates and other OpenCms developed code from these versions should mostly work “out of the box” with version 22.
Note for Alkacon OCEE users: Alkacon OCEE users will need a new OCEE version for OpenCms 22. The update is free for Alkacon customers with a current OCEE subscription. Please contact Alkacon to obtain the new version.
Further details about the switch to Jakarta
Compatibility with Java versions, servlet containers and databases
OpenCms 22 is compatible with Java 25 and 21.
The Jakarta OpenCms 22 variant requires a Java Servlet 5.0 compliant web container or higher. We have tested this release with Jetty and Tomcat. It works with Jetty 12 or Tomcat 10.
The legacy OpenCms 22 variant (Tomcat 9 / EE 8) requires a Java Servlet 4.0 compliant web container. We have tested this release with Jetty and Tomcat. It works with Jetty 12 or Tomcat 9.
Others have reported successful deployments of OpenCms on other web servlet containers like WildFly, GlassFish, WebLogic, WebSphere and Resin.
On the database side, we provide support for MySQL, MariaDB, Oracle, PostgreSQL, MS SQL Server, DB2 and HSQLDB.
Git branches and build tags for this release
The main OpenCms Git repository is available on Github at github.com/alkacon/opencms-core.
This release is tagged build_22_0_0. In case you want to get the most recent OpenCms sources from Github, please check out the branch main.
OpenCms is a leading Open Source Content Management System. The software has been in continuous development since 2000 and has an active community of open source developers.
OpenCms is a Java and XML based enterprise website content management solution built entirely from open source components. The user interface is completely browser based. OpenCms offers powerful and easy-to-use features that are particularly suitable for Internet or Intranet applications of large companies and organizations. OpenCms is open source software released under the LGPL license.
Alkacon Software GmbH & Co. KG from Cologne, Germany is the company responsible for the development of OpenCms. Alkacon Software provides training, support and add-on products for OpenCms. This provides our customers with additional security and convenience when using OpenCms in mission critical installations. For more information, please see the Alkacon product overview.
- The page editor allows WYSIWYG inline editing of web pages and arrangement of content by drag & drop.
- The form based editor allows editing of structured content in a well defined form mask.
- The sitemap editor allows creating new pages and rearranging the navigation tree by drag & drop.
- Responsive "Mercury" default template based on Bootstrap 5 with many features.
- Headless API for accessing content as JSON from external applications.
- Content creation for mobile devices with preview and device specific content control.
- Structured content can be defined using a simple XML schema.
- Easy to use "Online / Offline" workflow, changes must be approved before they become visible.
- Link management for all internal resources with broken link detection.
- Integrated image scaling and cropping.
- SEO features with automatic sitemap.xml generation and page alias support.
- Full featured user management that supports the concept of "Organizational Units" (OUs).
- Allows management of multiple websites within a single installation.
- Content can be served dynamically or exported to static HTML files.
- File access to the OpenCms content repository over WebDAV and CMIS.
- Integrates Apache SOLR for powerful content searching and noSQL like queries.
- Full text search for web pages as well as in office documents such as PDF, MS Office and Open Office.
- Extensions can be added through a flexible module system.
- The "time warp" feature allows to view resources which are expired or not yet released.
- JSP integration for dynamic functionality in templates, dynamic forms etc.
- ... and much more
If you find a security vulnerability, please report it to us by using our security vulnerability report form.
Please report other issues found in OpenCms using our GitHub issue tracker.
Contributions to the OpenCms core development are most welcome. Please submit your pull requests directly on GitHub.